VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,812)

page 25 of 1,041
  • CVE-2016-1000123CriOct 6, 2016
    risk 0.67cvss 9.8epss 0.04

    Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla

  • CVE-2015-8261CriJan 8, 2016
    risk 0.67cvss 9.8epss 0.04

    The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows remote attackers to conduct SQL injection attacks via a crafted SOAP request.

  • CVE-2008-3604CriAug 12, 2008
    risk 0.67cvss 9.8epss 0.04

    SQL injection vulnerability in bannerclick.php in ZeeBuddy 2.1 allows remote attackers to execute arbitrary SQL commands via the adid parameter.

  • CVE-2006-5603CriOct 30, 2006
    risk 0.67cvss 9.8epss 0.01

    SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

  • CVE-2025-8868CriSep 29, 2025
    risk 0.66cvss 9.8epss 0.24

    In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token.

  • CVE-2025-29085CriApr 2, 2025
    risk 0.66cvss 9.8epss 0.31

    SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.

  • CVE-2024-8522CriSep 12, 2024
    risk 0.66cvss 10.0epss 0.63

    The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied…

  • CVE-2024-5765CriJul 30, 2024
    risk 0.66cvss 9.8epss 0.27

    The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

  • CVE-2023-48084CriDec 14, 2023
    risk 0.66cvss 9.8epss 0.34

    Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.

  • CVE-2023-34991CriNov 14, 2023
    risk 0.66cvss 9.8epss 0.29

    A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.0 through 8.4.2 and 8.3.0 through 8.3.2 and 8.2.2 allows attacker to execute unauthorized code or commands via…

  • CVE-2023-31719CriSep 22, 2023
    risk 0.66cvss 9.8epss 0.27

    FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.

  • CVE-2023-34600CriJun 20, 2023
    risk 0.66cvss 9.8epss 0.24

    Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.

  • CVE-2023-30194CriMay 10, 2023
    risk 0.66cvss 9.8epss 0.32

    Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().

  • CVE-2022-35628CriJul 12, 2022
    risk 0.66cvss 9.8epss 0.26

    A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3.

  • CVE-2022-1281CriMay 2, 2022
    risk 0.66cvss 9.8epss 0.43

    The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.

  • CVE-2022-0349CriMar 7, 2022
    risk 0.66cvss 9.8epss 0.34

    The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection

  • CVE-2022-0651CriFeb 24, 2022
    risk 0.66cvss 9.8epss 0.32

    The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL…

  • CVE-2021-39378CriSep 1, 2021
    risk 0.66cvss 9.8epss 0.23

    A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the NamesList.php str parameter.

  • CVE-2021-30176CriApr 13, 2021
    risk 0.66cvss 9.8epss 0.29

    The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/devices/add endpoint.

  • CVE-2020-35848CriDec 30, 2020
    risk 0.66cvss 9.8epss 0.75

    Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.